Skip to content

feat(runtime): support trusted external agent launchers - #7940

Closed
shellz-n-stuff wants to merge 3 commits into
mainfrom
codex/plugin-runtime-support
Closed

shellz-n-stuff wants to merge 3 commits into
mainfrom
codex/plugin-runtime-support

Conversation

@shellz-n-stuff

@shellz-n-stuff shellz-n-stuff commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Superseded by the focused stack: #7942 → #7943 → #7944.

Summary

Allow trusted external launchers to run native Buzz agents with a fixed credential broker and a local TLS trust snapshot. When the optional launcher environment variables are absent, ordinary authentication and platform TLS behavior remain unchanged. No Sandpit engine, policy schema, plugin UI or plugin repository dependency is included.

  • Add a capability-authenticated loopback broker for the configured model service; the child can request a bearer or refresh a rejected bearer without accessing the credential cache.
  • Share optional local certificate verification between the agent and CLI. Missing or invalid snapshots fail closed; hostname verification stays enabled. MCP tools receive the trust snapshot path, not the broker capability.
  • Reuse endpoint resolution between runtime configuration and external launchers.
  • Include root and desktop lockfile entries for the small shared support crate.

Related issue

Related to #5286 (agent sandbox/container support). Searched existing open issues/PRs; no duplicate generic launcher support PR found. This does not implement a sandbox itself.

Testing

  • Focused synthetic checks pass: broker authorization, trusted TLS/hostname rejection and missing roots (3); endpoint resolution (1); CLI client regressions (12).
  • Public API documentation and independent review completed.
  • Mandatory push hooks passed on the updated base: branch freshness, file-size checks, native desktop checks and Rust tests.
  • Full repository just ci passed at 95fede847d0bec5427ededf6e5e1db9e18b35152: formatting/lint/static checks, Rust tests, desktop frontend tests/build, native desktop checks/tests, web build and mobile tests.
  • Hosted DCO Check passed; other hosted checks are still running.

Scope / remaining checks

No plugin publication is required. Hosted CI, DCO and human/code-owner review are still required. The real external plugin/model conversation is not claimed as validated by these synthetic tests.

Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
@github-actions

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is ebe99a46e8802b9ff20fdf6a1028ce93bdefaa43...95fede847d0bec5427ededf6e5e1db9e18b35152.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review 95fede847d0bec5427ededf6e5e1db9e18b35152 to authorize a new review.
Any previous review applies only to its recorded range.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant